← all publishers

grcengclub

@grcengclub source repo

78 published skills

  1. Dora Expert · grcengclub
    DORA expert for EU financial entities. Deep knowledge of Digital Operational Resilience Act including 5 pillars, ICT risk management, incident reporting, resilience testing, third-party oversight, and information sharing for financial sector digital resilience.
    0
    installs
  2. Gdpr Expert · grcengclub
    GDPR expert for EU privacy compliance. Deep knowledge of General Data Protection Regulation including 99 articles, 7 principles, 6 lawful bases, data subject rights, DPO requirements, DPIA, breach notification, cross-border transfers, and enforcement.
    0
    installs
  3. Glba Expert · grcengclub
    GLBA expert for financial institutions. Deep knowledge of Gramm-Leach-Bliley Act including Safeguards Rule (16 CFR Part 314), Privacy Rule (16 CFR Part 313), FTC enforcement, information security program requirements, vendor management, and consumer privacy notices.
    0
    installs
  4. Nydfs Expert · grcengclub
    NYDFS 23 NYCRR 500 expert for financial services. Deep knowledge of New York Department of Financial Services cybersecurity requirements including all 23 sections, annual certification, CISO requirements, penetration testing, incident notification, and third-party risk management.
    0
    installs
  5. Jp Appi Expert · grcengclub
    Japan APPI expert for the Act on the Protection of Personal Information. Reference-depth framework plugin with scope determination, evidence checklist, and SCF-backed assessment guidance for Japanese personal data.
    0
    installs
  6. Ind Dpdpa Expert · grcengclub
    India DPDPA expert for the Digital Personal Data Protection Act 2023 and the DPDP Rules 2025. Covers Data Fiduciary obligations, Data Principal rights, Significant Data Fiduciary regime, Consent Manager, breach notification (72-hour), cross-border transfer regime, children's data, sectoral overlap with RBI / SEBI / IRDAI / TRAI / CERT-In / ABDM, and Data Protection Board enforcement.
    0
    installs
  7. Sg Mas Trm Expert · grcengclub
    Singapore MAS Technology Risk Management Guidelines expert. Reference-depth framework plugin with scope determination, evidence checklist, and SCF-backed assessment guidance for Singapore-regulated financial institutions.
    0
    installs
  8. Singapore Pdpa Expert · grcengclub
    Singapore - Personal Data Protection Ac (PDPA) (2012) expert. Reference-depth framework plugin with assessment, scope determination, and evidence checklist — backed by the SCF crosswalk. Level up to Full by adding framework-specific workflow commands.
    0
    installs
  9. Drata Inspector Expert · grcengclub
    Interpret drata-inspector findings generated from drata-cli workflows and turn Drata control, monitor, evidence, personnel, and integration posture into GRC action.
    0
    installs
  10. Au Apra Cps 234 Expert · grcengclub
    APRA CPS 234 expert for Australian prudential information security. Reference-depth framework plugin with scope determination, evidence checklist, and SCF-backed assessment guidance.
    0
    installs
  11. Grc Engineering Club Design · grcengclub bundle
    Use this skill to generate well-branded interfaces and assets for GRC Engineering Club, either for production or throwaway prototypes/mocks/decks. Contains essential design guidelines, colors, type, fonts, assets, and UI kit components for prototyping the website, Academy, slides, social, and merch concepts.
    0
    installs
  12. Oscal Expert · grcengclub
    Expertise on OSCAL (Open Security Controls Assessment Language) — what document types exist, when to use each, schema versioning, FedRAMP/eMASS/CSPM integration, round-trip workflows.
    0
    installs
  13. Drawio · grcengclub
    Always use when the user asks to create, generate, draw, or design a diagram, flowchart, architecture diagram, ER diagram, sequence diagram, class diagram, network diagram, mockup, wireframe, UI sketch, GRC workflow, control map, audit process, risk register flow, compliance architecture, or mentions draw.io, drawio, drawoi, .drawio files, or diagram export to PNG/SVG/PDF.
    0
    installs
  14. Tprm Scorer · grcengclub
    Calculates vendor risk scores using inherent and residual risk factors. Generates risk ratings, comparisons, and treatment recommendations.
    0
    installs
  15. Socratic Drill · grcengclub
    Drills the user on a framework with application-level scenario questions. Inspired by mattpocock/skills/grill-me. Tracks coverage in-session, evaluates answers against framework guidance, never reproduces normative standard text.
    0
    installs
  16. Framework Tutor · grcengclub
    Tutor that produces working primers on GRC frameworks and roles. Adapts depth to the learner's background. Never reproduces copyrighted standard text — paraphrases and references control IDs.
    0
    installs
  17. Trust Center · grcengclub bundle
    Build and deploy a production-ready Trust Center for any company. Use this skill whenever someone asks to create a trust center, compliance portal, security page, or wants to publish their SOC 2/SOC 3/ISO 27001/HIPAA/compliance posture publicly. Also triggers when someone mentions gated document access for audit reports, NDA-based document sharing, or wants to replace paid trust center tools like Secureframe, Vanta, Drata, or SafeBase. Even if they just say "I need a place to share my SOC 2 with customers" — that's a trust center. Use this skill.
    0
    installs
  18. Control Tester · grcengclub
    Designs and documents control testing procedures. Creates test plans, executes walkthroughs, and documents results for audit workpapers.
    0
    installs
  19. Website Cicd · grcengclub
    Sets up GitHub Actions CI/CD workflow for automatic deployment to AWS on push to main. Uses GitHub OIDC for keyless AWS authentication.
    0
    installs
  20. Website Repo · grcengclub
    Creates a GitHub repository for the website project, initializes git, and pushes the code.
    0
    installs
  21. Control Explainer · grcengclub
    Explains a single control once and shows every framework it maps to via the SCF crosswalk. Resolves SCF IDs, framework-specific IDs, and plain-English descriptions. Never reproduces normative text.
    0
    installs
  22. Cmmc Expert · grcengclub
    CMMC v2.0 expert for DoD contractors. Covers NIST 800-171 Rev 2 (14 families, 110 controls), SPRS scoring, POA&M rules, 32 CFR Part 170, DFARS clauses, scoping, ESP/CSP, C3PAO assessment lifecycle, and Rev 2 → Rev 3 transition.
    0
    installs
  23. Irap Expert · grcengclub
    Australian IRAP (Information Security Registered Assessors Program) expert. Provides guidance on ISM controls, Essential Eight maturity levels, ACSC guidelines, and Australian data sovereignty requirements.
    0
    installs
  24. Pbmm Expert · grcengclub
    Canadian PBMM (Protected B, Medium Integrity, Medium Availability) expert. Provides comprehensive guidance on ITSG-33 controls, CCCS assessment, Canadian data residency, and Government of Canada cloud security requirements.
    0
    installs
  25. Soc2 Expert · grcengclub
    SOC 2 Trust Service Criteria expert. Provides guidance on Type I/II audits, control mapping, evidence requirements, and audit preparation for all Trust Service Categories.
    0
    installs
  26. Website Build · grcengclub
    Scaffolds a complete React/Vite website project from site-config.json. Generates components, styles, and configuration based on the site type and plan data.
    0
    installs
  27. Website Infra · grcengclub
    Deploys AWS CloudFormation infrastructure stacks for the website (S3, CloudFront, Route 53, ACM, and optionally contact form API).
    0
    installs
  28. Website Deploy · grcengclub
    Builds the React/Vite site, syncs to S3, and invalidates CloudFront cache. Uses the plugin's bundled deploy.sh script.
    0
    installs
  29. Ccm Expert · grcengclub
    CSA CCM expert for cloud security. Deep knowledge of Cloud Security Alliance Cloud Controls Matrix including 197 controls, 17 domains, CAIQ questionnaire, cloud service models (IaaS/PaaS/SaaS), shared responsibility, and framework mappings to ISO 27001, SOC 2, PCI-DSS, NIST.
    0
    installs
  30. Ismap Expert · grcengclub
    Japanese ISMAP (Information System Security Management and Assessment Program) expert. Provides guidance on ISO 27001/27017/27018 compliance, Japanese government cloud requirements, and data residency in Tokyo/Osaka regions.
    0
    installs
  31. Finding Generator · grcengclub
    Generates professional audit findings using the Condition-Criteria-Cause-Effect format. Creates management letter comments and remediation recommendations.
    0
    installs
  32. Grc Poam Diagram · grcengclub
    Use when creating a draw.io diagram for POA&M items, audit findings, remediation milestones, validation, closure, and escalation paths in a GRC, security, audit, compliance, privacy, cloud, or risk context.
    0
    installs
  33. Grc Raci Diagram · grcengclub
    Use when creating a draw.io diagram for responsibility assignments across GRC, security, engineering, legal, HR, procurement, vendors, and auditors in a GRC, security, audit, compliance, privacy, cloud, or risk context.
    0
    installs
  34. Policy Lifecycle · grcengclub
    Manages policy documents through their full lifecycle. Reviews policies for gaps, suggests updates based on framework changes, and tracks approval workflows.
    0
    installs
  35. Iso Expert · grcengclub
    ISO 27001 ISMS expert. Provides guidance on management system requirements, Annex A controls, certification process, and continuous improvement for information security.
    0
    installs
  36. Context Bootstrap · grcengclub
    Setup guidance for users running a /report:* command before their toolkit has enough context. Use when a report command detects missing findings, frameworks, or history. Walks the user through installation and first collection rather than generating a hollow report.
    0
    installs
  37. Compliance Tracker · grcengclub
    Tracks compliance status across multiple frameworks. Monitors control implementation, identifies gaps, and generates compliance dashboards and reports.
    0
    installs
  38. Website Preflight · grcengclub
    Validates AWS readiness for website deployment. Checks CLI tools, credentials, SES, Route 53, and ACM. Produces a report with pass/fail and action items.
    0
    installs
  39. So What Translation · grcengclub
    Translates GRC findings, risks, and program activity into language leadership actually reads. Use when any /report:* command is composing output intended for a CISO, CIO, or above. Opinionated rules on what lands and what doesn't.
    0
    installs
  40. Ch Fadp Expert · grcengclub
    Swiss Federal Act on Data Protection (nFADP) expert. Deep knowledge of the revised 2023 Swiss FADP including voluntary DSO, risk-based breach notification, individual criminal enforcement, Swiss transfer mechanisms, and key divergences from GDPR.
    0
    installs
  41. Access Review Triage · grcengclub bundle
    Access Review Triage
    0
    installs
  42. Cis Expert · grcengclub
    CIS Controls v8 expert for baseline security. Deep knowledge of 18 controls, 153 safeguards, Implementation Groups (IG1/IG2/IG3), and practical implementation guidance for organizations of all sizes.
    0
    installs
  43. Nist Expert · grcengclub
    NIST 800-53 control framework expert. Provides guidance on control families, baseline selection, tailoring, and federal compliance requirements including FedRAMP alignment.
    0
    installs
  44. Grc Data Flow Diagram · grcengclub
    Use when creating a draw.io diagram for regulated data flows, data classifications, storage, processing, transfer, access, retention, and logging in a GRC, security, audit, compliance, privacy, cloud, or risk context.
    0
    installs
  45. Risk Register Manager · grcengclub
    Manages organizational risk registers. Performs risk assessments, calculates risk scores, tracks mitigations, and generates risk reports for leadership.
    0
    installs
  46. Grc Portfolio Planner · grcengclub
    GRC-specific portfolio questionnaire that creates a site-config.json and SITE-PLAN.md tailored to GRC engineers — certifications, frameworks, audit experience, tools, and projects.
    0
    installs
  47. Grc Control Map Diagram · grcengclub
    Use when creating a draw.io diagram for controls mapped across frameworks, systems, owners, risks, and evidence sources in a GRC, security, audit, compliance, privacy, cloud, or risk context.
    0
    installs
  48. Exec Narrative Patterns · grcengclub
    Audience-specific tone and format guidance for leadership communications. Use when drafting any /report:* output to tune length, framing, and technical depth to the reader (board, audit committee, CEO, weekly CISO, regulator).
    0
    installs
  49. Risk To Jira Transformer · grcengclub
    Converts unstructured risk assessments into structured Jira tickets. Extracts Likelihood, Impact, Mitigation from natural language and generates JSON formatted for Jira API with clear Definition of Done criteria.
    0
    installs
  50. Grc Evidence Flow Diagram · grcengclub
    Use when creating a draw.io diagram for evidence collection, evidence lifecycle, audit evidence pipelines, and systems of record in a GRC, security, audit, compliance, privacy, cloud, or risk context.
    0
    installs
  51. Grc Audit Workflow Diagram · grcengclub
    Use when creating a draw.io diagram for audit planning, request lists, evidence, testing, exceptions, remediation, and reporting in a GRC, security, audit, compliance, privacy, cloud, or risk context.
    0
    installs
  52. Grc Risk Treatment Diagram · grcengclub
    Use when creating a draw.io diagram for risk intake, scoring, treatment, exception approval, residual risk, and monitoring workflows in a GRC, security, audit, compliance, privacy, cloud, or risk context.
    0
    installs
  53. Grc System Boundary Diagram · grcengclub
    Use when creating a draw.io diagram for compliance scope, authorization boundaries, trust boundaries, in-scope/out-of-scope systems, and system context diagrams in a GRC, security, audit, compliance, privacy, cloud, or risk context.
    0
    installs
  54. Evidence Artifact Collector · grcengclub
    Generates CLI commands and API scripts to collect point-in-time evidence for audit controls. Automates evidence gathering from cloud providers (AWS, Azure, GCP) and outputs formatted reports.
    0
    installs
  55. Nist AI Rmf Expert · grcengclub
    NIST AI 100-1 (AI RMF 1.0) expert. Stub-depth framework plugin that routes to the SCF crosswalk. Level up by adding framework-specific context, assessment workflow, and evidence patterns.
    0
    installs
  56. Nist Csf 20 Expert · grcengclub
    NIST Cybersecurity Framework v2.0 expert. Reference-depth knowledge of the six Functions (Govern, Identify, Protect, Detect, Respond, Recover), Categories and Subcategories, Profiles (Current vs Target), Tiers, Implementation Examples, and the practitioner workflow of using CSF as a board-readable cybersecurity outcomes language. Backed by the SCF crosswalk for control-by-control mechanics.
    0
    installs
  57. Us Nerc Cip Expert · grcengclub
    NERC Critical Infrastructure Protection expert. Reference-depth framework plugin with scope determination, evidence checklist, and SCF-backed assessment guidance for BES Cyber Systems.
    0
    installs
  58. Grc Third Party Risk Diagram · grcengclub
    Use when creating a draw.io diagram for vendor intake, tiering, questionnaires, security/privacy/legal review, contracting, and ongoing monitoring in a GRC, security, audit, compliance, privacy, cloud, or risk context.
    0
    installs
  59. Automation Coverage Analysis · grcengclub
    Composes week-over-week automation coverage narratives. Use when /report:automation-coverage is running. Frames the delta for leadership around time saved, quality of evidence, and forward-looking compounding value.
    0
    installs
  60. Cmmc Assessment Objectives · grcengclub
    Verbatim reference for all 320 NIST 800-171A Rev 2 assessment objectives, plus the Rev 2 → Rev 3 control crosswalk. Use for AO-level lookups (e.g., 3.1.1[c]), evidence planning, and forward-mapping to Rev 3. Pairs with cmmc-expert.
    0
    installs
  61. Program Portfolio Composition · grcengclub
    Patterns for synthesizing findings across multiple frameworks into one readable portfolio view. Use when a /report:* command is pulling from more than one framework plugin and needs to avoid drowning the reader in control IDs.
    0
    installs
  62. GCP Docs Expert · grcengclub
    GCP Docs Expert
    0
    installs
  63. Grc Framework Crosswalk Diagram · grcengclub
    Use when creating a draw.io diagram for mapping controls and obligations across frameworks to show overlap, gaps, and conflicts in a GRC, security, audit, compliance, privacy, cloud, or risk context.
    0
    installs
  64. Wiz Inspector Expert · grcengclub
    Wiz Inspector Expert
    0
    installs
  65. Us Hipaa Security · grcengclub
    HIPAA Security Rule expert for US healthcare compliance. Deep knowledge of 45 CFR Part 164 Subpart C, Administrative/Physical/Technical Safeguards, Required vs Addressable specifications, Risk Analysis, Business Associate Agreements, and HHS OCR enforcement.
    0
    installs
  66. Grc Shared Responsibility Diagram · grcengclub
    Use when creating a draw.io diagram for cloud/SaaS shared responsibility, inherited controls, provider controls, customer controls, and evidence ownership in a GRC, security, audit, compliance, privacy, cloud, or risk context.
    0
    installs
  67. Azure Inspector Expert · grcengclub
    Expertise in evaluating Azure subscription findings from azure-inspector and mapping them to SCF controls.
    0
    installs
  68. Slack Inspector Expert · grcengclub
    Interpret slack-inspector findings, explain Slack API coverage limits, and turn Slack workspace posture results into control evidence or remediation.
    0
    installs
  69. Splunk Inspector Expert · grcengclub
    Interpret splunk-inspector findings and translate Splunk retention, RBAC, audit, search ACL, and auth posture into compliance evidence and remediation.
    0
    installs
  70. Grc Compliance Operating Model Diagram · grcengclub
    Use when creating a draw.io diagram for high-level GRC program architecture, continuous compliance operating models, three lines of defense, and executive program maps in a GRC, security, audit, compliance, privacy, cloud, or risk context.
    0
    installs
  71. Datadog Inspector Expert · grcengclub
    Interpret datadog-inspector findings and translate Datadog monitoring, audit, log-retention, SSO, and RBAC results into GRC evidence and remediation.
    0
    installs
  72. Tenable Inspector Expert · grcengclub
    Interpret Tenable vulnerability-management findings for scan coverage, credentialed scans, vulnerability age, and scan access visibility.
    0
    installs
  73. Testssl Inspector Expert · grcengclub
    Interpret testssl-inspector normalized findings, recommend remediations, and tie evidence back to SCF anchor controls plus SOC 2 / NIST 800-53 r5 / PCI DSS 4.0.1 / ISO 27002:2022 equivalents derived from SCF crosswalks.
    0
    installs
  74. Academic Research Companion · grcengclub bundle
    Guide a research project through the full academic lifecycle — from raw idea to concrete research question, literature grounding, methodology, writing, feedback, and publication. Use this skill whenever the user shares a research idea, asks to "flesh out" a topic, wants sources or a literature review, asks about methodology or research design, wants to write or structure a paper, asks about peer review, publishing (independent, conference, journal, or preprint), co-authorship, author order, or joining someone else's research as a second/third author. Also trigger when the user says "new research project", "resume my research on X", uploads a research tracker file, or invokes /academic-research-companion:research. Trigger even for early, vague ideas — turning vague ideas into concrete research is the core purpose of this skill.
    0
    installs
  75. Snowflake Inspector Expert · grcengclub
    Interpret Snowflake account usage findings for MFA, network policies, masking/row access policies, session timeout, and retention.
    0
    installs
  76. AWS Secrets Inspector Expert · grcengclub
    Use when interpreting AWS Secrets Manager connector output, deciding between inspector and retrieve modes, drafting SCF-mapped controls for rotation / KMS / public-access / inactive-access findings, or troubleshooting an aws-secrets-inspector run.
    0
    installs
  77. Crowdstrike Inspector Expert · grcengclub
    Interpret CrowdStrike Falcon findings for sensor coverage, policy visibility, and host group scoping.
    0
    installs
  78. Cyber Essentials Plus Expert · grcengclub
    UK NCSC Cyber Essentials Plus (CE+) Expert
    0
    installs